{"repo":"toorandom/malhaus","free":true,"listed":false,"github":"https://github.com/toorandom/malhaus","clone":"git clone https://github.com/toorandom/malhaus.git","description":"Self-hosted malware static triage platform powered by LLMs","language":"Python","stars":24,"topics":[],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"Self-hosted malware static triage platform powered by LLMs. Upload a suspicious file or paste a URL — malhaus runs it through a pipeline of static analysis tools (radare2, YARA, strings, objdump, oletools, floss, binwalk, exiftool, optional Ghidra…), feeds the results to an LLM of your choice, and returns a structured verdict with confidence score, key reasons, and full tool output. Live demo: https://grothendieck.ff2.nl --- Features - PE, ELF, Office (OLE/OpenXML), PDF, PowerShell, shell script, JavaScript, JAR/WAR/EAR (Java) - Supports Gemini, OpenAI, Azure AI Foundry, Claude, DeepSeek , and any OpenAI-compatible server (Ollama, vLLM, LM Studio) - REST API with Bearer token authentication and per-key rate limiting - MCP server — AI agents (Claude, Cursor, Continue…) can call analyze natively - Mathematical analysis visualizations — entropy profile, compression curve, bigram matrix, and a 3D byte-trigram point cloud with HDBSCAN density clustering - Optional Ghidra headless decompilation (PE/ELF) - Result cache by SHA-256 — re-submitting the same file is instant - Captcha-protected web UI; API bypasses captcha with a token Mathematical analysis Every file is analysed through four independent visualizations derived purely from its byte sequence: - Entropy profile — sliding-window Shannon entropy) plotted across the file offset. Flat high-entropy regions indicate compression or encryption; structured dips reveal headers, overlays, or plaintext sections. See also Lyda & Hamrock","default_branch":null,"files":null,"tree":[],"storefront":"/r/toorandom","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/toorandom/malhaus/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}